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Abstract 

The proof of Toda's celebrated theorem that the polynomial hierarchy is contained in P# p relies 
on the fact that, under mild technical conditions on the complexity class C, we have 3C C BP ■ ®C. 
More concretely, there is a randomized reduction which transforms nonempty sets and the empty set, 
respectively, into sets of odd or even size. The customary method is to invoke Valiant's and Vazirani's 
randomized reduction from NP to UP, followed by amplification of the resulting success probability from 
l/poly(n) to a constant by combining the parities of poly(n) trials. Here we give a direct algebraic 
reduction which achieves constant success probability without the need for amplification. Our reduction 
is very simple, and its analysis relies on well-known properties of the Legendre symbol in finite fields. 

Valiant and Vazirani |VV86| gave a clever randomized reduction from NP to UP, the class of promise 
problems which have either a unique solution or no solution at all. Their reduction works as follows. Given, 
say, a 3-SAT formula </> on n variables, we begin choose an integer k uniformly from {1, . . . , n}. We then 
add the additional constraint that a hash function h takes the value zero, where h is chosen from a pairwise 
independent family of hash functions, and where a given truth assignment x obeys h(x) = with probability 
2~ k . If <fi is satisfiablc, then with probability fl(l/n) this additional constraint makes the solution unique. 

So long as the complexity class C is expressive enough to compute the hash function h and is closed under 
intersection, this reduction asserts that: 

3CCRP poly .3!C, 

where RP po i y denotes one-sided error with a l/poly(n) probability of success and where 3! denotes unique 
existence. Since 1 is odd, we can also write 

3CCRP poly • ©C, 

where, for instance, ©P is the class of decision problems which ask whether the number of witnesses for a 
problem in NP is odd. 

For the case of ©P, we can amplify the probability of success as follows: if we perform m = fi(n) 
independent trials of this reduction, then with probability fi(l) at least one trial will yield a formula <p' with 
a unique solution (assuming (j> is satisfiable). Since the expression 

m 

a = 1 + Y[{a t + 1) 

i=l 

is odd if and only if at least one of the is odd, and it is easy to implement such expressions within ©P by 
constructing m-tuples of witnesses, we conclude 



3 P C RP • © P 



where now the reduction works with probability ^(1). (Of course, by taking, say, m = n 2 , we can make the 
probability of success exponentially close to 1.) By showing that the operators BP and © can be commuted, 
we obtain Toda's result [Tod91j that 

PHCBP-ffiPC P# p . 

The purpose of this note is to give an alternate reduction from NP to RP® P which works with constant 
probability without the need for amplification. Our reduction is quite simple, and may be of independent 
interest. First, let p be a prime, let ¥ p denote the field of order p, and for a <E F p let x( a ) denote the Legendre 
symbol 

'0 ifa = 
x(a) = ^ +1 if a = b 2 for some 6^0 
T otherwise. 

If p has poly(n) digits, then x(°) can be computed in polynomial time as follows. Using modular exponen- 
tiation, calculate 

t = a (p-l)/2 modp 

Then x( a ) = +1 or — 1 if t = 1 or p — 1 = — 1 respectively. 
Now consider the following theorem. 

Theorem 1. Let S be a nonempty subset of¥ p of size \S\ = o{p 1 / 2 ). If b is chosen uniformly at random 
from F P; then the set 

S' = {xeS\ x (x + b) = -l} 
is of odd size with probability 1/2 — o(l). 

Proof. First note that, with probability 1 — \S\/p = 1 — o(n -1 / 2 ), we have x + b ^ for all x € S. Henceforth 
we will assume that this is the case. 

Then note that S' is of odd size if and only if 



\ X {x + b) = -I 



Since x is a multiplicative character, i.e., since x( a ^) = x( a )x(b), we can write this as 



X 



Y[(x+b))=-i. 



Then 



Pr [\S'\ is odd] = where T = E b X ( J| (x + b) j 



Now note that Ilzes^ + b) is & polynomial function of b. The expectation of a multiplicative character 
on the image of a polynomial on ¥ q is bounded by the following theorem, proved by A. Weil: 

Theorem 2 QWci48j). Let x be a multiplicative character of¥ p of order m > 1 (that is, m is the least 
integer for which x{ a ) m = 1 f or an U a )- Let f(b) G ¥ p [x] be a polynomial that is not the ruth power of a 
polynomial, and let d be the number of distinct roots of f in its splitting field over ¥ q . Then 

£*(/(&)) <(d-i) P 1/2 . 
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In our case, m = 2 and f(b) = Ilzes^ + Since this product gives a complete factorization of f(b) 
into distinct linear terms, f(b) is certainly not the square of a polynomial. Moreover, it has degree \S\, so 
d< \S\ = o{p 1 ' 2 ). Therefore, 

T=\Y.x{f{b)) = o{\) 

P bew p 

and \S'\ is odd with probability (1 -T)/2 = 1/2 - o(l). □ 
See also |LN97| §5] for further discussion. 

Our reduction works as follows. For concreteness, suppose we have a 3-SAT formula <j) on n variables. 
Choose a prime p > 2 cn for some c > 2, so that 2 n = ofj) 1 / 2 ). Interpret each truth assignment x as an n-bit 
integer x, choose b uniformly from F p , and add the constraint that x( x + b) = — 1. Then by Theorem [J if 
<p is satisfiable, the resulting formula <fj will have an odd number of satisfying assignments with probability 
1/2-0(1). 
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